CVE-2026-14691: SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection
A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function updatesettingsinfo of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[] leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14691?
The severity of CVE-2026-14691 is rated as medium with a score of 6.3.
What type of vulnerability is CVE-2026-14691?
CVE-2026-14691 is classified as a code injection vulnerability.
How do I fix CVE-2026-14691?
To fix CVE-2026-14691, sanitize user input in the update_settings_info function to prevent code injection.
What software is affected by CVE-2026-14691?
CVE-2026-14691 affects the SourceCodester Multi-Vendor Online Grocery Management System version 1.0.
What is the impact of exploiting CVE-2026-14691?
Exploiting CVE-2026-14691 can lead to unauthorized code execution through the manipulation of the content[] argument.